Entropy and likelihood-based detection of DGA generated domain names and their families

被引:1
|
作者
Bhatia A. [1 ]
Vishvakarma D.K. [2 ]
Kaushik R. [3 ]
Agrawal A. [1 ]
机构
[1] Department of Computer Science, BITS, Rajasthan, Pilani
[2] Center for Artificial Intelligence and Robotics (CAIR), DRDO, Karnataka, Bangalore
[3] Department of Electronics and Communication Engineering, Maulana Azad National Institute of Technology, Madhya Pradesh, Bhopal
关键词
botnets; C&C server; command and control servers; domain generations algorithms; domain name system;
D O I
10.1504/IJSN.2022.125512
中图分类号
学科分类号
摘要
Botnet is a network of hosts (bots) infected by a common malware and controlled by command and control (C&C) servers. Once the malware is found in an infected host, it is easy to get the domain of its C&C server and block it. To counter such detection, many malware families use probabilistic algorithms, known as domain generation algorithms (DGAs), to generate domain names for the C&C servers. In this paper, we propose a probabilistic approach to identify the domain names that are likely to be generated by malware using DGAs. The proposed solution is based on the hypothesis that the entropy of human-generated domain names should be lesser than the entropy of DGA generated domain names. Results show that the percentage of false negatives in the detection of DGA generated domain names using the proposed method is less than 29% across 39 DGA families considered by us in our experimentation. Copyright © 2022 Inderscience Enterprises Ltd.
引用
收藏
页码:147 / 192
页数:45
相关论文
共 50 条
  • [41] Likelihood-based artefact detection in continuously-acquired patient vital signs
    Colopy, Glen Wright
    Zhu, Tingting
    Clifton, Lei
    Roberts, Stephen J.
    Clifton, David A.
    2017 39TH ANNUAL INTERNATIONAL CONFERENCE OF THE IEEE ENGINEERING IN MEDICINE AND BIOLOGY SOCIETY (EMBC), 2017, : 2146 - 2149
  • [42] Likelihood-based object detection and object tracking using color histograms and EM
    Withagen, P
    Schutte, K
    Groen, F
    2002 INTERNATIONAL CONFERENCE ON IMAGE PROCESSING, VOL I, PROCEEDINGS, 2002, : 589 - 592
  • [43] Dictionary Extraction and Detection of Algorithmically Generated Domain Names in Passive DNS Traffic
    Pereira, Mayana
    Coleman, Shaun
    Yu, Bin
    DeCock, Martine
    Nascimento, Anderson
    RESEARCH IN ATTACKS, INTRUSIONS, AND DEFENSES, RAID 2018, 2018, 11050 : 295 - 314
  • [44] Detection of Algorithmically Generated Domain Names Using SMOTE and Hybrid Neural Network
    Zhang, Yudong
    Chen, Yuzhong
    Lin, Yangyang
    Zhang, Yankun
    COMPUTER SUPPORTED COOPERATIVE WORK AND SOCIAL COMPUTING, CHINESECSCW 2019, 2019, 1042 : 738 - 751
  • [45] A Semi-Supervised Learning Scheme to Detect Unknown DGA Domain Names based on Graph Analysis
    Yan, Fan
    Liu, Jia
    Gu, Liang
    Chen, Zelong
    2020 IEEE 19TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2020), 2020, : 1578 - 1583
  • [46] A Likelihood-Based Trait-Model-Free Approach for Linkage Detection of Binary Trait
    Basu, S.
    Stephens, M.
    Pankow, J. S.
    Thompson, E. A.
    BIOMETRICS, 2010, 66 (01) : 205 - 213
  • [47] Efficient split likelihood-based method for community detection of large-scale networks
    Wang, Jiangzhou
    Liu, Binghui
    Guo, Jianhua
    STAT, 2021, 10 (01):
  • [48] Detection of Algorithmically Generated Domain Names used by Botnets: A Dual Arms Race.
    Spooren, Jan
    Preuveneers, Davy
    Desmet, Lieven
    Janssen, Peter
    Joosen, Wouter
    SAC '19: PROCEEDINGS OF THE 34TH ACM/SIGAPP SYMPOSIUM ON APPLIED COMPUTING, 2019, : 1916 - 1923
  • [49] Algorithmically Generated Domain Names Detection Using Gated Recurrent Unit Deep Learning
    Nadagoudar, Ranjana B.
    Ramakrishna, M.
    JOURNAL OF ELECTRICAL SYSTEMS, 2024, 20 (07) : 469 - 481
  • [50] Detection of algorithmically generated malicious domain names using masked N-grams
    Selvi, Jose
    Rodriguez, Ricardo J.
    Soria-Olivas, Emilio
    EXPERT SYSTEMS WITH APPLICATIONS, 2019, 124 : 156 - 163